Hi All,
I am using Splunk ES. We create short Ids for notables.
How can we search the notables using short id as filter in incident dashboard on Splunk ES.
Within the ES app.
Select "Incident Review"
Look for the filter "Time or Associations", select Associations
A new filter option will appear. "Short ID"
Move 1 filter to the right with the name "Select". If you select this one, you can enter or select the Short ID you are looking for.